Tenda M3 Firmware vulnerabilities

44 known vulnerabilities affecting tenda/m3_firmware.

Total CVEs
44
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL17HIGH27

Vulnerabilities

Page 2 of 3
CVE-2022-38563HIGHCVSS 7.5v1.0.0.12\(4856\)2022-08-28
CVE-2022-38563 [HIGH] CWE-787 CVE-2022-38563: Tenda M3 V1.0.0.12(4856) was discovered to contain a heap buffer overflow vulnerability in the funct Tenda M3 V1.0.0.12(4856) was discovered to contain a heap buffer overflow vulnerability in the function formSetFixTools. This vulnerability allows attackers to cause a Denial of Service (DoS) via the MACAddr parameter.
nvd
CVE-2022-38565HIGHCVSS 7.5v1.0.0.12\(4856\)2022-08-28
CVE-2022-38565 [HIGH] CWE-787 CVE-2022-38565: Tenda M3 V1.0.0.12(4856) was discovered to contain a heap buffer overflow vulnerability in the funct Tenda M3 V1.0.0.12(4856) was discovered to contain a heap buffer overflow vulnerability in the function formEmailTest. This vulnerability allows attackers to cause a Denial of Service (DoS) via the mailpwd parameter.
nvd
CVE-2022-38571HIGHCVSS 7.5v1.0.0.12\(4856\)2022-08-28
CVE-2022-38571 [HIGH] CWE-787 CVE-2022-38571: Tenda M3 V1.0.0.12(4856) was discovered to contain a buffer overflow in the function formSetGuideLis Tenda M3 V1.0.0.12(4856) was discovered to contain a buffer overflow in the function formSetGuideListItem.
nvd
CVE-2022-38567HIGHCVSS 7.5v1.0.0.12\(4856\)2022-08-28
CVE-2022-38567 [HIGH] CWE-787 CVE-2022-38567: Tenda M3 V1.0.0.12(4856) was discovered to contain a stack overflow vulnerability in the function fo Tenda M3 V1.0.0.12(4856) was discovered to contain a stack overflow vulnerability in the function formSetAdConfigInfo. This vulnerability allows attackers to cause a Denial of Service (DoS) via the authIPs parameter.
nvd
CVE-2022-38566HIGHCVSS 7.5v1.0.0.12\(4856\)2022-08-28
CVE-2022-38566 [HIGH] CWE-787 CVE-2022-38566: Tenda M3 V1.0.0.12(4856) was discovered to contain a heap buffer overflow vulnerability in the funct Tenda M3 V1.0.0.12(4856) was discovered to contain a heap buffer overflow vulnerability in the function formEmailTest. This vulnerability allows attackers to cause a Denial of Service (DoS) via the mailname parameter.
nvd
CVE-2022-32040HIGHCVSS 7.5v1.0.0.122022-07-01
CVE-2022-32040 [HIGH] CWE-787 CVE-2022-32040: Tenda M3 V1.0.0.12 was discovered to contain a stack overflow via the function formSetCfm. Tenda M3 V1.0.0.12 was discovered to contain a stack overflow via the function formSetCfm.
nvd
CVE-2022-32041HIGHCVSS 7.5v1.0.0.122022-07-01
CVE-2022-32041 [HIGH] CWE-787 CVE-2022-32041: Tenda M3 V1.0.0.12 was discovered to contain a stack overflow via the function formGetPassengerAnaly Tenda M3 V1.0.0.12 was discovered to contain a stack overflow via the function formGetPassengerAnalyseData.
nvd
CVE-2022-32043HIGHCVSS 7.5v1.0.0.122022-07-01
CVE-2022-32043 [HIGH] CWE-787 CVE-2022-32043: Tenda M3 V1.0.0.12 was discovered to contain a stack overflow via the function formSetAccessCodeInfo Tenda M3 V1.0.0.12 was discovered to contain a stack overflow via the function formSetAccessCodeInfo.
nvd
CVE-2022-32037HIGHCVSS 7.5v1.0.0.122022-07-01
CVE-2022-32037 [HIGH] CWE-787 CVE-2022-32037: Tenda M3 V1.0.0.12 was discovered to contain a stack overflow via the function formSetAPCfg. Tenda M3 V1.0.0.12 was discovered to contain a stack overflow via the function formSetAPCfg.
nvd
CVE-2022-32039HIGHCVSS 7.5v1.0.0.122022-07-01
CVE-2022-32039 [HIGH] CWE-787 CVE-2022-32039: Tenda M3 V1.0.0.12 was discovered to contain a stack overflow via the listN parameter in the functio Tenda M3 V1.0.0.12 was discovered to contain a stack overflow via the listN parameter in the function fromDhcpListClient.
nvd
CVE-2022-32036HIGHCVSS 7.5v1.0.0.122022-07-01
CVE-2022-32036 [HIGH] CWE-787 CVE-2022-32036: Tenda M3 V1.0.0.12 was discovered to contain multiple stack overflow vulnerabilities via the ssidLis Tenda M3 V1.0.0.12 was discovered to contain multiple stack overflow vulnerabilities via the ssidList, storeName, and trademark parameters in the function formSetStoreWeb.
nvd
CVE-2022-32035HIGHCVSS 7.5v1.0.0.122022-07-01
CVE-2022-32035 [HIGH] CWE-787 CVE-2022-32035: Tenda M3 V1.0.0.12 was discovered to contain a stack overflow via the function formMasterMng. Tenda M3 V1.0.0.12 was discovered to contain a stack overflow via the function formMasterMng.
nvd
CVE-2022-32034HIGHCVSS 7.5v1.0.0.122022-07-01
CVE-2022-32034 [HIGH] CWE-787 CVE-2022-32034: Tenda M3 V1.0.0.12 was discovered to contain a stack overflow via the items parameter in the functio Tenda M3 V1.0.0.12 was discovered to contain a stack overflow via the items parameter in the function formdelMasteraclist.
nvd
CVE-2022-26290CRITICALCVSS 9.8v1.0.0.12\(4856\)2022-03-24
CVE-2022-26290 [CRITICAL] CWE-78 CVE-2022-26290: Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the co Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/WriteFacMac.
nvd
CVE-2022-27079CRITICALCVSS 9.8v1.0.0.12\(4856\)2022-03-24
CVE-2022-27079 [CRITICAL] CWE-77 CVE-2022-27079: Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the co Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/setPicListItem.
nvd
CVE-2022-27083CRITICALCVSS 9.8v1.0.0.12\(4856\)2022-03-24
CVE-2022-27083 [CRITICAL] CWE-77 CVE-2022-27083: Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the co Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /cgi-bin/uploadAccessCodePic.
nvd
CVE-2022-27077CRITICALCVSS 9.8v1.0.0.12\(4856\)2022-03-24
CVE-2022-27077 [CRITICAL] CWE-77 CVE-2022-27077: Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the co Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /cgi-bin/uploadWeiXinPic.
nvd
CVE-2022-27078CRITICALCVSS 9.8v1.0.0.12\(4856\)2022-03-24
CVE-2022-27078 [CRITICAL] CWE-77 CVE-2022-27078: Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the co Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/setAdInfoDetail.
nvd
CVE-2022-26289CRITICALCVSS 9.8v1.0.0.12\(4856\)2022-03-24
CVE-2022-26289 [CRITICAL] CWE-78 CVE-2022-26289: Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the co Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/exeCommand.
nvd
CVE-2022-27080CRITICALCVSS 9.8v1.0.0.12\(4856\)2022-03-24
CVE-2022-27080 [CRITICAL] CWE-77 CVE-2022-27080: Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the co Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/setWorkmode.
nvd